
maltrail
Real-time malicious traffic detection system using public blacklists, static malware trails, and heuristic analysis to identify threats across DNS,…

Real-time malicious traffic detection system using public blacklists, static malware trails, and heuristic analysis to identify threats across DNS,…

System-independent library for user-level packet capture and filtering. Provides a portable framework for low-level network monitoring, security…

Automated threat intelligence aggregation tool that extracts and normalizes indicators from multiple sources (OSINT feeds, malware reports) into a…

Real Intelligence Threat Analytics (RITA) is a framework for detecting command and control communication through network traffic analysis.

Botnet monitoring is a crucial part in threat analysis and often neglected due to the lack of proper open source tools. Our tool will provide an open…

Read-only WordPress security scanner for HestiaCP servers. Detects wp2shell compromise indicators (CVE-2026-63030 / CVE-2026-60137) across all hosted…

Arkime is an open source, large scale, full packet capturing, indexing, and database system.

Training-free anomaly detection framework using Shannon Entropy, Fisher Information, and Wasserstein Distance to map system states into geometrically…

SQL powered operating system instrumentation, monitoring, and analytics.

Rust tool to detect cell site simulators on an orbic mobile hotspot

🍯 T-Pot - The All In One Multi Honeypot Platform 🐝

Centralized network visibility and continuous asset discovery. Monitor devices, detect change, and stay aware across distributed networks.

JA4+ is a suite of network fingerprinting standards


A curated list of resources related to Industrial Control System (ICS) security.

IntelMQ is a solution for IT security teams for collecting and processing security feeds using a message queuing protocol.


A modular, skill-based autonomous Security Operations Center (SOC) agent that monitors OpenSearch/Elasticsearch data, builds RAG-based behavioral…